Ravid Circus on Building an Efficient Remediation Strategy
By centralizing and orchestrating remediation efforts, organizations can eliminate bottlenecks, improve efficiency and strengthen their security posture. Learn more from Ravid Circus, co-founder and chief product officer at Seemplicity.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Textron tv.
Our next guest on Textron tv today is Ravi Circus. Ravi is the co-founder, chief product officer at a company called Sea Simplicity, SEEM, simplicity. Hey, Ravi, welcome to Text Drug tv.
Man, it's great to have you on. Hey, uh, nice to be here. Thank you so much.
Good. It's, uh, it's my pleasure. Just fixing my button here.
Um, so Ravi, let's start off with a little bit about you. If it's okay, I said you're the co-founder, chief product officer at Simplicity, but what, give us an idea of your journey. Well, so I, I'm on the cybersecurity market for like 25 years.
All, all of them is both of the very large side, but I also been a practitioner for many years in global 2000 companies. My entire career is, uh, around network security, vulnerability management, cloud security. Um, some people know, uh, will say that I know to do only one thing, but I think I know it.
I know it's very good. Um, so, so, so, yeah, and, and a lot of those experiences and, and learnings that, that I had over the last, uh, 20 years are the things that kind of, uh, make me co co-founder with my, with my team and, and build the simplicity, uh, as we are trying to, to solve old problems in, uh, in, in a new and very effective, uh, a very effective way. Absolutely.
You know, vulnerability management, remediation is something I've been involved with, uh, since like 2003, I guess, is, you know, a company I had helped start, we came out with a product called vm, vulnerability Assessment of Management. Back then, Nessus was still open source. Everyone had Nessus, you know, under the hood, you know, writing Nale scripts or what have you.
But what I remember back then, Ravi, was it seems so natural to us that finding vulnerabilities in and of itself was nice, but not perfect. Remediating vulnerabilities was the game. And even back then, we were trying to automate remediation, and we ran into such resistance, right, from people who said, whoa, whoa, whoa, whoa, whoa.
You can't just patch, or you just can't shut something down, or you can't reroute something. You know, we've gotta make sure it doesn't break something else, because what you break is a lot more valuable than what can be attacked via the vulnerability, right? And it was, it was frustrating even back then.
I, you know, and I was there. This is a company I also helped co-found, and I was there for 10 years, and it was, or maybe eight years, but it was extremely frustrating. Um, I'm, I'm sensing that maybe Simplicity has a, a new approach, a better approach that breaks down that resistance.
Tell us a little about the company. Yeah, I, I think you, that's a great point. I think that if you look at it, the security team is responsible to discover vulnerabilities, but they are not authorized to fix them.
The people that can actually are add other guys, the it, the developers, the DevOps, the operations, and the reality is that the security team sits in the mi in the middle, responsible for the process, but cannot execute the process. So they are all day trying to, what we call drive remediation, or in other words, making other people work for them. And throughout the many years of the practices of vulnerability management, everyone was too focused on the, on the security team as the one which are responsible for the process, rather than to be focused on the fixing team or the remediation team are the one that actually executing the program.
And one of the things that we did when we started Simplicity is actually go and interviews those DevOps guys, those it gals, those, the network operations guys, and kind of understanding their perspective to this process and how we can make it easier for them. Because if we'll make it easier for them to fix, we will make it easier to the security team, the security organization. And by doing that, we actually developed a platform that takes all that huge data, but prepare it better for remediation, make it available in the way that those remediation and fixing teams wants it, as opposed to, as opposed to just throw another list of big problems that only security team understands, uh, and expect them to do the most out of it.
Uh, absolutely, and you're right, that that was the problem, right? It's the, you know, the, the responsibility without power, if you will. And, and quite frankly, in the cloud, it was even worse at some level, right?
Because, you know, some vulnerabilities were beyond your, your company's even ability to remediate. Um, yeah, I think Cloud, by the way, got it much worse because one of the things that happens on the cloud is that the modern cloud team actually got full stack responsibility for the networking, for operating system, for infrastructure, just not for security. Those security guys keep their things close to their chest, don't tell anyone, and it it once every while they give you two vulnerabilities that you need to fix today, right?
Of course, this will create the friction. So, so cloud and the dynamics and doing things much faster actually accelerate and, and accelerate this problem and, and, and increase the friction very between the teams very dramatically. Absolutely.
You know what, we've done a great job of what we call setting the table here, right? So tell me about simplicity. So we in simplicity actually look at the problem as so, so traditionally people looking vulnerability management problem.
As a prioritization pro, we actually look at this problem as a process productivity, uh, problem as a communication and collaboration problem. Part of it is to prioritize, of course, if you want to be more productive, more effective, you want, you want, you need to prioritize what you're doing. But it doesn't end only there.
We are, we have bit of platform that we call remediation operations that actually takes the data from all those different scanners, whether it's code cloud, on-prem, SaaS, IOT, all the different misconfigurations vulnerabilities, application security issues. We put them into the platform and using different technologies that involve, involve data scientists, that involve ai, that involve our best practices and knowledge. We have better a platform that transformed the findings into solutions, into list, list of action items.
And then we have built in a, a, a workflow platform and automated the, uh, um, dispatching platform that actually manage the security backlog for each of the remediation team. So no more, uh, Excel reports, no more PDF reports, no more status meetings, just a rolling backlog of security issues. Just like you have your bugs, your features, you now have a backlog of security issues that manage itself.
And you don't need to go through that motion of, here is a list of problems, go figure out. And, and, and next month we will review the list again to, to try and understand what we do. We have reduced dramatically the friction, we improve the efficiency, and we are getting to a point that our customers report five or six times more remediation in their organization comparing to without simplicity, we are getting to the point where three or four people can handle remediation processes with team of 200 or with 200 or 250 development teams in a very large organization, which otherwise won't, uh, won't scale.
Sounds like Nirvana, man. I, I, you know, uh, from back in my day, it's like, wow, okay, so what, what's the special sauce, if you will? What, what is, what, what was the game changer here?
So I, I think there are a couple of, I, I think there are a couple of, uh, things that, that we are doing that, uh, that make the difference. There are three main things. I think the first one is that we are transforming findings into fixes, into remediation items.
'cause many problems has the same solution. Many problems are effectively can be remediated better in, in the same way. If you have a piece of code that have three other problem, three problems, it doesn't make sense to get one problem today, one problem next week, one problem the week after, because you will have to QA that piece of code three times.
Actually, it'll be much more efficient to the organization to get everything together now, so you can test it only once. Uh, and in very similar way to vulnerabilities than others. So what we are first doing is that we are transforming the list of problems into remediation items.
That's actually reduced the amount of things that you handle in about 70 to 8% in average on our, on our customer, uh, base. The second thing is a set of algorithms, which we call find the fixer. One of the ma main problems of, uh, of any organization is that you know, who you have a problem, you know where the problem is, you just don't know who can fix it.
So we have developed a different algorithms that use data science, uh, science a algorithms, a AI capabilities and, and, and other, and other techniques that actually allows us to look on data that already exists in the organization. Activity, all tickets and what have you, to actually understand who is the fixer with the owner of that, uh, resource or asset. And then to be able to automatically assign that, uh, remediation item, uh, uh, to those.
And the third part is really our, uh, our workflow engine, which actually makes the data remediation data available to each and every one of the remediation teams in any way they want. Because if you will go to the organization today, one team will want tickets in Jira, others will want alerts in in Slack. The third one will want an API to pull it to their platform, and the fourth one will come and say, I want to log into a web UI and just mark all the things that I, that I did.
And the security team cannot scale to deliver different type of remediation plans to each of the remediation teams. So they're going to the lowest common dominator, which is a spreadsheet. So what we actually do, the third piece is our remediation router that actually make the data available.
However, the remediation team, uh, wants to look at that. So less, uh, significantly less amount of findings, knowing who the fixer is and make the data available, uh, for the fixing team in any way that they will want to help them remediate faster. I love it.
Good stuff. Now of course, we live in a world where it just seems there's, every day there's more, more and more like the, the pace of vulnerabilities is increasing, right? No matter how you want to slice and dice it, it just seems almost like shoveling sand against the tide, right?
Where we it for every one we fix three more pop up, right? How can you, and, and given this environment and all of the things you cited, everybody has their, every team has their own way of fixing these, their own way of approaching it. How do you build a enterprise level efficient strategy here?
I mean, obviously say use simplicity, but you know, beyond using ity. So, so I, I think, I think, again, I think it includes many different things. I think one of the things that you need to focus at is actually not is what my current risk, but actually how quickly I recover from it.
So to stop thinking on how secure organization is, but start thinking about how resilient my organization is. And as you start to thinking about resiliency, you can count and say, okay, though there are set of things of those, uh, tons of, uh, findings of tons of vulnerabilities. I want to be fixed within 30 days.
There is a bunch of things within a quarter, and there is a big backlog that, uh, maybe within a year and start to measure that the things that are important for you actually get into the hands of the right person at the right time at the, with the right data so he can fix it in 30 days. Then to make sure that there is a good plan for that quarterly things, and then, uh, what to do with all the rest when you're doing technology refresh. The, if, if you start, if you stop thinking about how do I protect myself now and start thinking about how I build organiza, uh, an organization that helped me to recover from a zero day that was identified right now, and I know that within a week my organization is secured against that, it actually make a, a big difference because you are starting to find the inefficiencies in the process rather than a big pile of vulnerabilities that you try to sort what will be next.
And by putting process automation into place, putting a lot of prioritization into place, putting a lot of, uh, a, a reduction of the noise into place, that what actually allows you to, to build the process that allows you to make sure that the organization is effectively fixing to measure that, to identify bottlenecks. And by doing that, uh, building a more resilient organization. Excellent.
Ravi, we're, we're, we're running all on time for people who want to engage with simplicity, first of all, a website. Second of all, like how, how did they get started? Did they, you know, gi give us, you know, an on-ramp?
So, so it is very easy. Of course, you can go to the website, you can reach out to me in, uh, in LinkedIn or any of my, uh, of my, uh, my team members. Actually, many of the customers just come and ask us, guys, let's, let's run it through our organization.
Let's see what the efficiencies that, that, that that we get. And we are going go, going with them for a quick test trial when we onboard three or four different, uh, data source of vulnerabilities or application security or cloud security issues. And almost immediately you see that reduction in 70 and 80% of the, of the findings.
Almost immediately. You see that one finding that you know about for two or three weeks that you don't, but you don't know who should fix it. And, and, and then, and suddenly simplicity is showing you what is that?
So, so I think that the, the best way is let us prove that, uh, that it works the way that, uh, that we claim it is okay, just engage with us, with us. We will be more than happy to do a test, uh, test run together, uh, with the customer, with his data just to prove that things can be better. You can actually manage that at scale and not manually one by one through through a spreadsheet.
Generally. How long does it take to get sort of a, a, a, uh, trial like that set up? Uh, the, the, the setup is like, uh, two to three days, and customers are kind of playing with the platform for two weeks just to make sure that they see data over time, uh, that they're getting their feedback.
We are recommending the customer is to involve non-security people in the, in the, in that test Sure. To get developers, those itdo, DevOps into the place so they can give their feedback, they can see the benefits. So, so you should, so you could take technically to take two to three days.
That organization usually play with the tool for two or three weeks just to get the, the arm around it. It's very easy, uh, in that sense. It doesn't require any agents installation or something more complex than that.
So it is more, it is very easy to, to try and see the benefits yourself. Excellent. Ravi, thanks for coming on Tech Drug TV and TAG telling us about simplicity.
Um, continued success. Are you guys gonna be at RSA conference? Yes, for sure.
Well, we'll be there live. Stop by, say hello. We'll be our broadcast alley all week.
I will. Looking Forward, Ravi Circus, co-founder, chief product officer at Simplicity. Uh, they might have cracked the nut on getting remediations for your vulnerabilities.
io. We're gonna take a break on text Drunk Gang. We'll be back in a little bit.